The UK Home Automation Archive

Archive Home
Group Home
Search Archive


Advanced Search

The UKHA-ARCHIVE IS CEASING OPERATIONS 31 DEC 2024


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Fw: [OT] Firewall configuration...


  • To: ukha_d@xxxxxxx
  • Subject: Fw: [OT] Firewall configuration...
  • From: "Gareth Cook" <gcook@xxxxxxx>
  • Date: Thu, 27 Dec 2001 11:56:43 +0000
  • Delivered-to: mailing list ukha_d@xxxxxxx
  • Mailing-list: list ukha_d@xxxxxxx; contact ukha_d-owner@xxxxxxx
  • Reply-to: ukha_d@xxxxxxx


Geneally, the disallow everything is last in the list - always have your denies after your allows. The last one being deny everything.

Also, think about blocking icmp, etc. We have a NAT system here at work, so I allow that address range (or our cisco PIXs) more freedom to my system.

G.
Gareth Cook
Senior Engineering Specialist

EMEA ED, IBM SWG
Lotus Park, Staines, TW18 3AG
Office:  +44 (0) 1784 445 166
Mobile:  +44 (0) 7980 445 166
Fax:      +44 (0) 1784 499 166
Work: g@xxxxxxx
Personal:
g@xxxxxxx
AIM Chat : TheBoyG
MSN Chat : chat@xxxxxxx


----- Forwarded by Gareth Cook/UK/IBM on 27/12/2001 11:51 -----
Discussion
Main Topic

"Paul Gordon" <paul_gordon@xxxxxxx>
Today 11:50

.
Subject:
.
[ukha_d] [OT] Firewall configuration...
.
Category:



OK chaps, time to get my firewall sorted out I guess....

Currently it's wide open, with just one rule (block all NetBIOS)

I'm planning to add a default rule which blocks EVERYTHING, then add
specific rules to open up individual ports/services as required... (is this
the best configuration?)

Looking for any "gotchya's" from those of you who've done this, - are there
any port numbers I should leave open that I might not have considered? (What
port does MSN Messanger use?)

Paul G.


_________________________________________________________________
Join the world’s largest e-mail service with MSN Hotmail.
http://www.hotmail.com



Home | Main Index | Thread Index

Comments to the Webmaster are always welcomed, please use this contact form . Note that as this site is a mailing list archive, the Webmaster has no control over the contents of the messages. Comments about message content should be directed to the relevant mailing list.